VDB
KO
MEDIUM

GHSA-7f4j-64p6-5h5v

Traefik affected by HTTP/2 CONTINUATION flood in net/http

Quick fix

GHSA-7f4j-64p6-5h5v — github.com/traefik/traefik/v2: upgrade to the fixed version with the command below.

go get github.com/traefik/traefik/v2@v2.11.2

Details

There is a potential vulnerability in Traefik managing HTTP/2 connections.

More details in the [CVE-2023-45288](https://www.cve.org/CVERecord?id=CVE-2023-45288).

## Patches

- https://github.com/traefik/traefik/releases/tag/v2.11.2 - https://github.com/traefik/traefik/releases/tag/v3.0.0-rc5

## Workarounds

No workaround

## For more information

If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/traefik/traefik/v2
Introduced in: 0 Fixed in: 2.11.2
Fix go get github.com/traefik/traefik/v2@v2.11.2
Go / github.com/traefik/traefik/v3
Introduced in: 3.0.0-rc1 Fixed in: 3.0.0-rc5
Fix go get github.com/traefik/traefik/v3@v3.0.0-rc5

References